PT-2024-12630 · Hcl · Hcl Dryice Lucy

Published

2024-05-10

·

Updated

2024-07-03

·

CVE-2023-37526

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions HCL DRYiCE Lucy (now AEX) (affected versions not specified)
Description The issue is related to a Cross Origin Resource Sharing (CORS) misconfiguration in the mobile app, which could allow unauthorized access to application resources from any web domain and enable cache poisoning attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-37526

Affected Products

Hcl Dryice Lucy